SAA-C03 exam dumps

SAA-C03 practice question 57 of 553

AWS Certified Solutions Architect - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAA-C03 Question 57

Select 3

A financial services company is building a new web application that requires user authentication and authorization. The application also needs to monitor its AWS environment for potential security threats and ensure that sensitive customer data stored in Amazon S3 is secure and monitored for any anomalies. Which combination of AWS services should the company use to meet these requirements?

  1. A

    Amazon Cognito to handle user authentication and authorization

  2. B

    Amazon GuardDuty to monitor for potential security threats

  3. C

    Amazon Macie to classify and monitor sensitive data stored in Amazon S3

  4. D

    AWS WAF to protect the application from common web exploits

  5. E

    AWS Identity and Access Management (IAM) to manage user access to the application

Show answer and explanation

Correct answers: A, B, C

Explanation

The company needs to address three specific requirements: user authentication and authorization, threat detection, and sensitive data monitoring. Amazon Cognito provides user authentication and authorization capabilities, Amazon GuardDuty monitors for security threats in the AWS environment, and Amazon Macie identifies and protects sensitive data in Amazon S3. These services together meet the scenario's requirements effectively, while AWS WAF and IAM, although valuable for other purposes, are not the best fit for the described use cases.

  • A. Correct.

    Amazon Cognito is designed to handle user authentication and authorization, making it suitable for managing user sign-up, sign-in, and access control for the web application.

  • B. Correct.

    Amazon GuardDuty is an intelligent threat detection service that monitors AWS accounts, workloads, and data for potential security threats, which is crucial for the company's AWS environment.

  • C. Correct.

    Amazon Macie is designed to help identify and secure sensitive data in Amazon S3 by using machine learning to classify and monitor data, making it the right choice for protecting sensitive customer data.

  • D. Incorrect.

    While AWS WAF can protect the application from web exploits, it is not specifically required for the use cases mentioned in the scenario, such as user authentication, threat detection, and sensitive data monitoring.

  • E. Incorrect.

    IAM is a foundational AWS service for managing access to AWS resources, but it does not provide the specific functionality needed for user authentication, threat detection, or sensitive data monitoring in this scenario.

Timed practice exam

Take a SAA-C03 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam